Trust center

Privacy, security, and access.

Practical controls based on GDPR principles, U.S. privacy and security guidance, state-law common denominators, and accessible web practice.

01

Privacy by default

Optional first-party and Google analytics remain off until consent. Global Privacy Control and Do Not Track are honored.

02

Data minimization

Public forms exclude regulated records, the site does not store raw visitor IP addresses, and card data stays on Stripe-hosted checkout.

03

Individual rights

A dedicated request workflow tracks access, correction, deletion, portability, restriction, opt-out, appeal, verification, and response dates.

04

Security baseline

HTTPS, security headers, restricted staff access, audit history, spam controls, error monitoring, backups, and retention controls reduce common risks.

05

Accessible design

Semantic structure, keyboard operation, visible focus, reduced motion, labeled forms, responsive layouts, and an accessibility feedback channel are built in.

06

Operational boundaries

The site is not represented as a HIPAA, FDA Part 11, NHS clinical, manufacturing, quality-system, or universal legal-compliance platform.

Important limitation

Compliance depends on facts and operations.

No website can guarantee blanket compliance with every federal, state, international, industry, accessibility, or customer-specific rule. Applicability depends on business size, data, location, contracts, vendors, and use. Mithra maintains a common control foundation and requires qualified legal and security review for regulated or high-risk deployments.